Show TOC

User Administration and Identity Management in ABAP SystemsLocate this document in the navigation structure

With the user administration, you create the prerequisites for your employees being able to work in the SAP system.

Create a user master record for every employee. In addition to technical administration data, the user master record includes the authorizations included in roles and profiles that allow the user to execute actions in the SAP system.

Getting Started

For information about the fundamentals of user and authorization administration in ABAP systems, see the SAP Library under  AS ABAP Authorization Concept.

Tools

The most important tools for user and role maintenance are listed below:

  • User Maintenance (transactions SU01, SU10)

  • Role Maintenance (transaction PFCG)

  • Indirect role assignment using HR-ORG

  • User Information System (transaction SUIM)

  • Central User Administration (transactions PFCG, SM59, SU01, SCUA, SCUM, SCUG, SUGR, SCUL)

Tasks

The central tasks of user and role maintenance are listed below:

Table 1: User and Role Maintenance Tasks
Task Information

Maintain users (create, change, delete, and so on)

User Maintenance Functions

Maintain roles (create, change, delete, and so on)

Role Maintenance Functions

Assign roles to users

Assigning Roles

Mass changes of user data

Mass Changes

Logging off inactive users

Logging Off Inactive Users

Maintain Internet users

Creating and Maintaining Internet Users

Setting Password Controls

Logon and Password Security in the SAP System

These tasks go beyond purely administering the users of the ABAP systems but, depending on the system landscape, may affect user administration.

Table 2: Identity Management Tasks
Task Information

Setting up and operating Central User Administration

Central User Administration

Setting up a directory service and synchronizing the ABAP user administration with an LDAP-compatible directory service

Directory Services (BC-SEC-DIR)

Although the following tasks go beyond daily user administration, they are necessary for successful long-term operation.

Table 3: More Complex Tasks
Task Information

Comparing Users

Compare user master records

Using the central repository for personalization data

Central Repository for Personalization Data

Maintaining defaults and options for users

Maintaining User Defaults and Options

Using the User Information System

User Information System

Performing a first installation

First Installation Procedure

Performing an upgrade

Checking for Changes in Authorizations After Upgrades